Extraterritorial Scope
Extraterritorial scope describes how a law can apply to organizations located outside the country or region that enacted it. For example, some data protection rules can reach a company based abroad if it handles the personal data of people located within the regulating jurisdiction. Being subject to such a law and being able to enforce it in practice are two different matters.
Extraterritorial scope refers to the legal reach of a regulation over controllers or processors established outside the enacting jurisdiction, based on connecting factors defined in the instrument itself. Under the EU GDPR, Article 3 sets out territorial scope, applying the Regulation to processing carried out in the context of the activities of an establishment of a controller or processor in the Union; the EDPB has separately examined the practical extent to which the GDPR can be enforced against actors outside the EU, indicating that reach and effective enforcement are distinct questions. Other instruments define their own scope on their own terms and are not interchangeable with the GDPR: the EU AI Act sets its scope in Article 2, covering actors inside and outside the EU, and US instruments addressing extraterritorial access to data operate under separate legal frameworks. This entry defines the concept of extraterritorial reach only; it does not cover the full application criteria of Article 3, the designation of a representative, cross-border transfer mechanics, retention rules, or the mechanics and outcomes of enforcement, which are governed separately and vary by jurisdiction.
Why it matters
Extraterritorial scope matters because an organization's physical location no longer determines which data protection laws it must consider. A company headquartered outside the European Union may still fall within the reach of the EU GDPR where its processing occurs in the context of the activities of an establishment in the Union, as set out in Article 3. This means that compliance planning cannot rely solely on where servers, offices, or legal entities sit; it must account for the connecting factors that each instrument defines for itself.
Crucially, being subject to a law and having that law effectively enforced against you are distinct questions. The European Data Protection Board has separately examined the extent to which the GDPR can be effectively enforced by data protection authorities against actors outside the EU, which underscores that legal reach and practical enforcement do not automatically coincide. Organizations should not treat limited enforcement reach as a safe harbor, nor assume that falling outside a law's practical enforcement means falling outside its scope; the two assessments serve different purposes.
The concept also cuts across multiple, non-interchangeable regimes. The EU AI Act defines its own scope in Article 2, covering actors both inside and outside the EU, and US instruments addressing extraterritorial access to data operate under separate legal frameworks entirely. Treating one instrument's scope rules as a proxy for another's is a common and consequential error, because each defines its territorial reach on its own terms.
Who it's relevant to
Inside Extraterritorial Scope
Common questions
Answers to the questions practitioners most commonly ask about Extraterritorial Scope.